Courseiva

CKS Minimize Microservice Vulnerabilities Practice Question

Which TWO of the following are valid Pod Security Context settings to harden a container? (Select 2)

⚠ Common exam trap

A common misconception is that setting `runAsUser: 0` is a hardening measure because it 'specifies a user,' when in fact it sets the container to run as root, the most dangerous user.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

runAsNonRoot: true

Setting `runAsNonRoot: true` in the Pod Security Context forces the container to run with a user ID (UID) other than 0 (root). This is a fundamental hardening measure that prevents an attacker who gains code execution inside the container from having root privileges, thereby limiting the blast radius of a compromise. It is a recommended practice in the CIS Benchmark for Kubernetes and directly addresses the principle of least privilege.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    privileged: true

    Why it's wrong here

    Setting `privileged: true` runs the container in privileged mode, granting it all capabilities and disabling most security mechanisms like seccomp, AppArmor, and SELinux. This is equivalent to running the process as root on the host, making it a serious security risk. It is not a security hardening measure but rather a way to bypass security.

  • ✗

    runAsUser: 0

    Why it's wrong here

    Setting `runAsUser: 0` explicitly runs the container process as the root user (UID 0), which escalates privileges within the container. This is risky because root in the container may leverage capabilities to access host resources if kernel protections are insufficient. It is not a security context setting that enhances security; instead, it is a misconfiguration that should be avoided.

  • ✓

    runAsNonRoot: true

    Why this is correct

    Setting `runAsNonRoot: true` enforces that the container process runs as a non-root user by rejecting the image's default user if it is root. This prevents the container from gaining root privileges inside the container, reducing the attack surface. It is a valuable security context setting recommended in Pod Security Standards.

  • ✓

    readOnlyRootFilesystem: true

    Why this is correct

    Setting `readOnlyRootFilesystem: true` mounts the container's root filesystem as read-only, preventing writes to the filesystem and blocking malicious modifications or persistence. Applications must write to ephemeral volumes or external storage if needed. This is a valid security context setting that enhances container immutability and limits the impact of a compromised process.

  • ✗

    allowPrivilegeEscalation: true

    Why it's wrong here

    Setting `allowPrivilegeEscalation: true` permits a container process to elevate its privileges beyond those of its parent process, such as through setuid-executable gains. This can enable an attacker to achieve root access even if the container runs as a non-root user. The secure default is to set it to false, so this setting is not considered a valid security control.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.